home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!dove!ariel.ncsl.nist.gov!wack
- From: wack@ariel.ncsl.nist.gov (John Wack)
- Newsgroups: comp.security.misc
- Subject: Re: anonymous ftp checklist
- Message-ID: <7033@dove.nist.gov>
- Date: 20 Nov 92 14:50:43 GMT
- References: <1992Nov12.142251.9131@hubcap.clemson.edu> <16987@umd5.umd.edu> <84008@ut-emx.uucp>
- Sender: news@dove.nist.gov
- Organization: National Institute of Standards & Technology
- Lines: 17
-
-
- I'd recommend that you ftp to cert.org -- they have a checklist for
- anonymous ftp and, since they're running their own anonymous ftp
- and are a likely target for crackers, it contains some good advice.
- Unfortunately, I can't locate my own copy right now, otherwise I'd
- include it here. But, I'd take a look at what they have to say.
-
- Well, as long as I'm typing, another thing I'd recommend is to use
- a non-stock ftpd that does better logging and access control. We're
- using the one from wuarchive.wustl.edu, which logs transfers and
- many other items (configurable) and also uses an access-control file
- that will allow you to disable ftp based on load, time of day, point
- of origin, etc. You might want to take a look at that as well.
-
- Good luck,
- John Wack
-
-